THE OBSERVATORY — THE SEE FACULTY OF SOLORA

See the work without standing in it.

The always-current, shared, legible picture of live Solora — for everyone who needs to watch the work without being in it. A read-projection of the one ledger: no separate store, no rollup, no summary. What leadership sees is the record itself.

GRADED · LIVE  the single-operator read surfaces run today · DECLARED · FRONTIER  the org-scale, trust-rendering observatory is the build ahead.

THE SEE SURFACE — ONE LEDGER, READ, NOT REPORTED

Not a report of the work. The work's own record.

Solora splits into two surfaces on purpose: makers do the work in their own tools over MCP, and the org sees it online. The observatory is that online SEE surface — a read-projection of the one ledger, scoped by org and membership, never a copy. Because there is one ledger underneath, the picture is always-current by construction: no sync, no export, no after-the-fact rollup. What leadership sees is the record, not a summary of it. It is the SEE surface of Solora, the one place many makers work — many makers, one ledger →

That is the whole promise: a superior can answer "what are our humans and agents committed to right now, and is it holding?" by looking, in real time, at an honest record — instead of calling a status meeting or hovering over a maker's shoulder. One ledger, two projections: the makers write it, the org reads it. There is no rollup step in between to drift, lag, or lie.

Solora is a view of the one stream — never a second store to keep in sync, never a weekly rollup assembled from motion. The transitions become the picture directly.

THE ORRERY — THE APPARATUS MADE LEGIBLE

Every goal, a body in orbit.

The centerpiece is the living orrery: every goal in a workspace rendered as a body in an orbital view, drawn from the org's real ledger — not placeholder stand-ins. A body exists on that canvas because a goal exists in the record; an arc exists because the record declared that relation.

  • Position. The root goal is the sun; its children hang in rings outward, radius from depth in the containment tree, each subtree owning a contiguous sector.
  • Colour and size. Colour from engagement — open, satisfied, archived. Size from tier: portfolio ≫ objective ≫ initiative ≫ task.
  • Glow and spark. Glow from the live work sitting on the body; a spark when agents are working there right now.
  • Physics, from behind the one sealed seam. Spin, brightness, acceleration and phase are five bounded numbers computed off-box and scrubbed at the door — the only judgement in this product that is not open. The sealed seam →
  • What it does NOT draw, rather than faking. There is no "recommended next leaf" ring, because nothing on this seam publishes a recommendation; no rose clashed body, because the shipped vocabulary is open/satisfied/archived and there is no clashed to paint; and no apparatus hash, because a plausible-looking hex string is the cheapest possible lie for a surface whose whole claim is that it does not invent.
  • DECLARED · FRONTIER Trajectory trails and cosmic-zoom. Bodies leaving trails over time, and a view that scales from one repository to a whole fleet without changing its language. Neither is built; the orrery draws one org's goal tree in its current frame.

THE ASKA LENSES — THREE READINGS OF ONE RECORD

Not three datasets. One record, seen three ways.

Every lens holds the same axis: intent-vs-reality — what was promised, next to what reality returned.

01

Story

The record grouped by goal: what was committed under each aim, what happened, how it graded.

02

Stream

What moved most recently: binds, claims, starts, grades and retractions, newest first.

03

Track

The counts, and only the counts — held, missed, and indeterminate kept as its own column, seeded at zero so a rate you have never earned is still visible as a rate.

This page named six lenses until 2026-08-15 — Story, Stream, Stacks, Track-Record, Graph, Files. Three of those six were never built: Stacks and Graph read units of work (crucibles, waves) that do not exist in the shipped ledger, and Files reads a path-to-binding index nothing writes. They are declared below rather than deleted, because what a reader was promised is part of the record too.

  1. DECLARED · FRONTIERStacks — the work grouped into larger units. Gated on those units existing: the shipped ledger organizes work by goal, and nothing above the goal tree.
  2. DECLARED · FRONTIERGraph — how intents, commits and contradictions connect. Gated on the clash concept, which nothing computes today.
  3. DECLARED · FRONTIERFiles — the work seen through the paths it touched. Gated on an intent recording the paths it moved; today an intent records a commitment and a test, not a path set.

Four more lenses ship beside these three, and they are not readings of the record at all: the planner's goal tree, the coordination plane, which machines are installed enough to work, and each box with what runs on it. The editor tab is a mock, and carries DECLARED · FRONTIER wherever it appears.

A commit view shows what changed; the observatory shows what was promised and whether the promise held.

That comparison is the whole point — and it exists only because the intent was bound in falsifiable form before the work. How intent is bound →

FORGEBLAME + THE NAV-SPINE — DECLARED, NOT BUILT

What was this line committed to — and did it hold?

DECLARED · FRONTIER  None of this section ships. There is no ForgeBlame in the product, no nav-spine, and no narration layer. What gates all three is the same missing edge: an intent records a commitment and a falsifiable test, not the paths or lines it moved. Until a satisfier pointer carries a path set, there is nothing to join a line of code to a commitment with. It is written out below because it is what we are building toward and a reader deserves to see the target — not because any of it runs.

For a line of code, git-blame shows who and when. ForgeBlame shows the human-or-agent authorship, plus the binding it satisfied, plus that binding's grade, its falsifiable test, and the evidence chain back to the artifact that answered it.

Not just who wrote this, but what was it committed to, and did that commitment hold. It records what was committed and whether the bound test held — faithful, not omniscient. It does not claim the work was right; it shows the promise and its grade, and lets you read the evidence.

Chat-blame tells you an agent touched the line. ForgeBlame tells you the commitment that line was answering — and how it graded when reality resolved.

FORGEBLAME · services/invoice/pdf.ts · NOT BUILT

  1. agent mira-2L42 · bound "renders invoice PDF under 400 ms" — test held at termSATISFIED
  2. danaL58 · bound "export ships behind a flag" — flag present at termSATISFIED
  3. agent bexL91 · bound "migration reverses in one command" — reverse failed on stagingVIOLATED
  4. agent kelL114 · bound "never serves a stale invoice" — test still openSATISFYING
  5. agent orunL120 · bound "drop the legacy export path" — retracted after a values-tensionRETRACTED

A sketch of an unbuilt surface, not a screenshot. Git-blame shows the first column today; the three that follow it are the declared build.

The nav-spine. The git rail and the living orrery are both functions of a single cursor. Scrub the timeline and the code history, the bindings in flight, and the orbital view move together on one time axis: commit ↔ binding ↔ crucible. There is no jumping between a commit log in one tool and intent in another — they are one spine.

Narration. A thin layer that re-voices only already-graded facts into readable prose — a plain-language telling of what the ledger already records. It may re-phrase a graded outcome, never assert one. It narrates the record; it does not add to it.

Narration re-voices facts the ledger already carries; it never invents a grade. The record stays the authority — the prose is only a reading of it.

THE AT-RISK CENSUS + THE TRUST STATE

Calibrated bookkeeping. Open trust.

The at-risk census. DECLARED · FRONTIER A calibrated read of which open commitments are most likely to not land. Nothing computes this today. It is written here as the target, and the bar it would have to clear is stated with it, because the bar is the whole difference between bookkeeping and prophecy: it would have to be calibrated — a "70% at-risk" meaning about seven in ten such commitments actually miss, measured against this record's own resolved history and published as a measurement. A number that has not been calibrated is a guess wearing a percentage sign, and we would rather ship nothing here than that. What gates it is volume: a calibration curve needs resolved commitments to fit against. the record it would learn from →

The trust state — declared, not shipped. The attestation layer is frontier: when it lands, the observatory will render whether each maker's client is honoring the ritual — standard cryptography on the immutable ledger: a signed manifest hash, a challenge/response, per-action tokens. The ledger vouches for the ritual, so people don't have to watch people. Trust becomes a legible property of the shared record, not a thing a manager polices in person.

What the record does hold today is a verdict per repository, not per session — which is a narrower claim than this page used to make, and a true one.

Repository stateWhat the record shows
installedEvery artifact of the ritual is present and byte-for-byte what we render — the gate is in place.
driftedThe artifacts are there and no longer match: stale, partial, or edited.
absentNothing of the ritual is present.
verified / unverifiedSeparately, and on our side: whether every commit that entered the branch after the boundary commit carries a receipt signed by a key the organization enrolled — never a key list read out of the repository, because anyone who can push can edit content.
  1. GRADED · LIVEthe orrery over one org's goal tree, the three ledger lenses, the coordination plane, and the two machine reads — each of them a live read of one org's record over the same seam, with an empty read rendered as empty rather than as zero
  2. GRADED · LIVEthe gate in the repository and the guard over it — a commit naming no bound intent refused locally, and the range re-walked server-side against enrolled keys from a boundary commit no pusher can move
  3. DECLARED · FRONTIERForgeBlame, the nav-spine, narration, the at-risk census, and the Stacks / Graph / Files lenses — none of them built; each gated above on the edge it is missing
  4. DECLARED · FRONTIERper-session attestation — the manifest fingerprint is deterministic today; the exchange around it (challenge/response, per-action tokens, trust tiers) is the remaining build

The read surfaces are real and they read one org's live record; what is not real is the layer above them that would join a line of code to the commitment it answered. We label it, we do not sell it as shipped.

WHAT IT IS DELIBERATELY NOT

The healthy version of oversight.

This is the two-surface split made concrete: a superior sees, in real time, that the team's clients are running the enforced discipline — without inspecting anyone's machine or watching anyone work. It exists to make work trustable, not to watch people.

The observatory is never

  • Not a surveillance dashboard. It shows committed intent, graded outcome, and attestation state — not keystrokes, not activity heat-maps, not who typed what when.
  • Not where makers work. The heavy making lives in the maker's own tools over MCP; the observatory is the shared view and a light coordination layer, never the place an engineer is forced to author.
  • Not a status meeting reconstructed after the fact. It is the live record itself, always-current — not a weekly rollup assembled from motion.
The interface between maker and superior is the ledger record, not the person. A team that remembers — never a panopticon.

One world, read in order. See the whole →